Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-46328— apparmor: fix rlimit for posix cpu timers

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于apparmor模块对posix cpu定时器的rlimit处理不完整,可能导致资源限制设置不当。

CVSS 7.3 · High EPSS 0.11% · P2

Possible ATT&CK Techniques 1 AI

T1068 · Exploitation for Privilege Escalation

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux baa73d9e478ff32d62f3f9422822b59dd9a95a21< e1cc11550b2f66687a374536c9dfdddcefca0efe affected
baa73d9e478ff32d62f3f9422822b59dd9a95a21< 2232d7cd243833ad750cae656d1817fe43744a09 affected
baa73d9e478ff32d62f3f9422822b59dd9a95a21< 28aa93fcfb33b6d580c5df4ae8b6d13fb0e6fcd3 affected
baa73d9e478ff32d62f3f9422822b59dd9a95a21< 1f736dfe27c857b78f8461cd7c3dd9640be74b37 affected
baa73d9e478ff32d62f3f9422822b59dd9a95a21< e43818b16815c0c2bf933ef28316f8e704e5e0ef affected
baa73d9e478ff32d62f3f9422822b59dd9a95a21< 9bf1fa150775b0c6b794e4b6a2c0395e13777999 affected
baa73d9e478ff32d62f3f9422822b59dd9a95a21< 57d51d41b90eface809b72e0e009b50546492f1f affected
baa73d9e478ff32d62f3f9422822b59dd9a95a21< 6ca56813f4a589f536adceb42882855d91fb1125 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-46328

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
apparmor: fix rlimit for posix cpu timers
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: apparmor: fix rlimit for posix cpu timers Posix cpu timers requires an additional step beyond setting the rlimit. Refactor the code so its clear when what code is setting the limit and conditionally update the posix cpu timers when appropriate.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于apparmor模块对posix cpu定时器的rlimit处理不完整,可能导致资源限制设置不当。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux baa73d9e478ff32d62f3f9422822b59dd9a95a21 ~ e1cc11550b2f66687a374536c9dfdddcefca0efe -
Linux Linux 4.10 -

II. Public POCs for CVE-2026-46328

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-46328

登录查看更多情报信息。

Patches & Fixes for CVE-2026-46328 (8)

Same Patch Batch · Linux · 2026-06-09 · 21 CVEs total

CVE-2026-46325 9.8 CRITICAL RDMA/rxe: Fix iova-to-va conversion for MR page sizes != PAGE_SIZE
CVE-2026-46316 9.3 CRITICAL KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry
CVE-2026-46317 8.8 HIGH KVM: arm64: Reassign nested_mmus array behind mmu_lock
CVE-2026-46326 8.4 HIGH iio: pressure: mprls0025pa: fix spi_transfer struct initialisation
CVE-2026-46332 8.0 HIGH greybus: gb-beagleplay: bound bootloader receive buffering
CVE-2026-52907 7.8 HIGH media: rockchip: rkcif: fix off by one bugs
CVE-2026-46319 7.8 HIGH net/sched: act_ct: Only release RCU read lock after ct_ft
CVE-2026-46330 7.8 HIGH Revert "net/smc: Introduce TCP ULP support"
CVE-2026-46327 7.8 HIGH dm: fix unlocked test for dm_suspended_md
CVE-2026-46324 7.8 HIGH netfilter: nf_tables: use list_del_rcu for netlink hooks
CVE-2026-46323 7.8 HIGH net: gro: don't merge zcopy skbs
CVE-2026-52906 7.7 HIGH 9p: fix access mode flags being ORed instead of replaced
CVE-2026-46320 7.4 HIGH tap: free page on error paths in tap_get_user_xdp()
CVE-2026-46322 7.1 HIGH tun: free page on build_skb failure in tun_xdp_one()
CVE-2026-46321 7.1 HIGH tun: free page on short-frame rejection in tun_xdp_one()
CVE-2026-46329 erofs: handle end of filesystem properly for file-backed mounts
CVE-2026-46318 Revert "mm/hugetlbfs: update hugetlbfs to use mmap_prepare"
CVE-2026-52904 drm/nouveau: fix nvkm_device leak on aperture removal failure
CVE-2026-52905 mm/damon/core: disallow non-power of two min_region_sz on damon_start()
CVE-2026-46315 io_uring/waitid: clear waitid info before copying it to userspace

IV. Related Vulnerabilities

V. Comments for CVE-2026-46328

No comments yet


Leave a comment